oss-sec mailing list archives

CVE request - open-vm-tools using predictable filename in /tmp


From: Michael Scherer <misc () zarb org>
Date: Mon, 26 Oct 2015 19:23:21 +0100

Hi,

It seems that vm-support, from open-vm-tools use /tmp to
store output of diagnostic software.

See 
https://github.com/vmware/open-vm-tools/blob/master/open-vm-tools/scripts/common/vm-support#L200

Can a CVE be assigned ?

-- 
Michael Scherer


Current thread: